logoalt Hacker News

pocksuppettoday at 2:28 AM2 repliesview on HN

If there's going to be a single point of failure in front of your website, that single point of failure may as well be the only single point of failure instead of having two single points of failure, and it's probably important that people can't spoof responses.


Replies

akerl_today at 2:35 AM

Nobody had to hack it. A system at DENIC broke, and so Cloudflare turned off DNSSEC validation for all of their users accessing .de. If DNSSEC was actually important for the security model of those users, that would be a huge deal.

tptacektoday at 2:39 AM

This is a non sequitur.